Ultimate magazine theme for WordPress.

Exploited MEV Bot Causes $2 Million Loss in Curve Pool Swaps: Data

According to data from PeckShield Alert, an unknown Miner Extractable Value (MEV) bot has fallen victim to a hack that caused a loss of approximately $2 million.

The incident, which occurred in the renowned Curve pools, led to several large swaps and subsequent reverse swap arbitrage.

Attacker manipulates Curve Pool

The exploitation occurred when the arbitrage function 0xf6ebebbb() lacked proper authentication, providing an open door for the attacker to manipulate swaps across multiple Curve pools. This malicious activity resulted in significant deviations and caused significant losses to the affected parties.

As the situation progressed, the attacker cleverly reversed the exchanges to maximize his profits, further exacerbating the impact of this incident.

The attacker exploited an arbitrage bot, resulting in a loss of $2.3 million by the Curve pool. They discovered an exposed feature within the bot that allowed them to initiate a Wrapped Ether (WETH) to Wrapped Bitcoin (WBTC) transaction.

They then executed a quick loan of 27,255 WETH (equivalent to $51.36 million) and used it to significantly manipulate the WETH/WBTC price ratio within the Curve pool.

By destabilizing the pool, the attacker forced the arbitrage bot to convert 1,339.8 WETH (approximately $2.52 million) into 6.95 WBTC (approximately $244,000).

It is important to note that the owner of the MEV bot had already withdrawn funds from the contract before the attack.

Curve Finance Previous Exploits

On July 30, 2023, a series of exploits occurred across multiple Curve Finance liquidity pools, resulting in losses of approximately $70 million. This incident caused significant concern in the DeFi community. The attacks were made possible by a vulnerability in Vyper, a third-party Pythonic programming language used by Ethereum smart contracts, including those used by Curve and other decentralized protocols.

It is important to note that after the initial incident, both white hat hackers and MEV (Miner Extractable Value) bot operators worked together to recover some of the lost funds. As a result, the final value of losses may be lower than suggested in the initial reports.

Less than a week after the exploit, the hacker returned 4,820 alETH and 2,258 ETH to Alchemix, equivalent to about $12.7 million.

On August 6, 2023, Curve Finance announced via Twitter that the deadline for the hacker to voluntarily return the remaining funds had passed. As a result, the company expanded its $1.85 million bounty offer to anyone who could identify the hacker.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: